Skip to content

Security & Privacy Incident Log (Pointer)

UK GDPR Art 33/34. Controls SEC-13. Status: not started.

Tier 2 — pointer only. Real incident records contain sensitive operational detail and possibly personal data; they must not be stored in this repo. They live in the restricted store. This file records only the process and a non-identifying index.

Policy: policies/incident-response-policy.md. Playbook: procedures/incident-response-playbook.md.

Process (to be designed — SEC-13)

  • Detection → triage → containment → eradication → recovery → post-mortem.
  • Breach-notification clock: 72 hours to the ICO from awareness (Art 33), where the breach is likely to risk individuals' rights; affected-individual notification without undue delay where high risk (Art 34).
  • Severity ladder, on-call owner, and comms templates: see procedures/incident-response-playbook.md (drafted).
  • Every incident gets a blameless post-mortem filed in the restricted store; the non-identifying summary and any control changes are reflected here and in the control register.

Non-identifying index (when live)

Ref Date Severity Category ICO notified? Individuals notified? Restricted post-mortem
(none yet)

Restricted store location: [to be designated] (Tier 2).